The Pharmacy and Poisons Board’s new guideline on medical device software gives Kenya real, detailed rules for AI-enabled health tools for the first time. It does not give those rules a new statutory foundation. Software as a Medical Device sits in Kenya today on a guideline issued under a 1957 statute never written with software in mind, and a company relying on that guideline should understand exactly where it is solid ground and where it is not.
A Guideline Sitting on an Old Statute
The Pharmacy and Poisons Board’s authority ultimately traces back to the Pharmacy and Poisons Act, Cap 244, a statute whose text is built around drugs, poisons, and the professionals who handle them, not medical devices and certainly not software. Kenya has no standalone medical devices Act. Device regulation, including the new Medical Device Software guideline published on 16 April 2026, exists as PPB administrative guidance rather than as a regulation made under a statute that expressly defines “medical device” or “software” in its own text. That is a materially different legal footing from a gazetted statutory instrument. A guideline can generally be revised or withdrawn by the regulator issuing it far more easily than a regulation can, and a company relying on it should treat it as current expectation rather than settled law with the enforcement certainty of a statutory provision. This is precisely the structural gap the pending Health Products and Technologies Regulatory Authority Bill is designed to close: as originally drafted, it would repeal the Pharmacy and Poisons Act outright and create a new Authority with jurisdiction expressly extending to medical devices, in-vitro diagnostics, and digital health products, an authority the current PPB regime does not clearly have on the face of its own founding statute. Until that Bill passes the Senate and receives assent, Kenya’s SaMD framework runs on guidance layered onto a statute that predates it by nearly seventy years.
Registration Assumes a Fixed Product
Kenya’s device registration model, including the five-year registration certificate and the post-market variation-notification process built for physical devices, was designed around a product that does not change after approval. A pacemaker approved today is, materially, the same pacemaker in year four of its certificate. An adaptive AI model is not. The Medical Device Software guideline’s own answer to this, requiring manufacturers to define permitted model evolution and build in rollback capability, is a genuine attempt to address the mismatch, but it is a guideline-level patch on a registration architecture that was never rebuilt around continuously changing products. Whether PPB’s existing variation-notification process, designed for a manufacturer changing a physical specification, actually functions well for a model that updates itself between scheduled reviews is an open operational question this article cannot resolve from published materials alone, and a company should raise it directly with PPB rather than assume the guideline has fully solved it.
A Second, Separate Compliance Track
An AI-enabled SaMD that processes patient data to train or monitor itself does not only face PPB device regulation. It separately triggers Kenya’s Data Protection Act 2019, which requires registration as a data handler for any organisation processing health data, regardless of company size, since the small-business exemption under the 2021 Regulations does not apply to health administration or patient care processing. Where the underlying data includes genetic or other especially sensitive categories, a Data Protection Impact Assessment becomes a separate mandatory step under regulation 49 of the 2021 General Regulations. Neither obligation is addressed by the Medical Device Software guideline itself, which is a PPB instrument focused on device safety and performance, not data protection. A company building an AI SaMD in Kenya is really managing two parallel regulatory tracks, PPB device classification and ODPC data handler registration, and treating the MDSW guideline as the complete compliance picture will leave a real gap.
An Unresolved Liability Question
Kenya has no reported case law or specific statutory provision allocating liability when an AI-enabled device produces an autonomous erroneous output that harms a patient, as distinct from an ordinary product liability claim over a static, non-adaptive device. Existing tort principles around negligence and product liability would presumably apply in some form, but how a court would treat a continuously learning model that behaved differently at the point of harm than it did at the point of PPB approval is genuinely untested here. A company deploying an adaptive AI tool in Kenya should not assume its existing product liability insurance and contractual indemnity structures, likely drafted for conventional software or hardware, adequately anticipate this scenario.
How We Can Help
Clay & Associates Advocates advises digital health companies on the full compliance picture for AI-enabled products in Kenya, spanning device regulation, data protection, and liability structuring. Our companion piece, Regulating AI-Enabled Medical Devices: A Preview of What’s Coming to the PPB, covers the guideline itself in detail, and our piece on the Health Products and Technologies Regulatory Authority Bill covers the pending legislation that would finally give device regulation, including software, an explicit statutory foundation. Contact our Life Sciences & Healthcare practice to map both your device compliance and data protection obligations before launch.
Sources: Pharmacy and Poisons Act, Cap 244; Pharmacy and Poisons Board, Guideline on Regulation of Medical Device Software in Kenya (MDSW), 16 April 2026; Health Products and Technologies Regulatory Authority Bill; Data Protection Act, No. 24 of 2019, section 18; Data Protection (General) Regulations, 2021, Legal Notice 263 of 2021, regulations 13 and 49.
Frequently asked questions
Is Kenya’s Software as a Medical Device framework based on a dedicated statute?
No. It rests on a Pharmacy and Poisons Board guideline issued under the Pharmacy and Poisons Act, Cap 244, a 1957 statute that does not itself define medical devices or software. The pending Health Products and Technologies Regulatory Authority Bill would create a dedicated statutory basis if enacted.
Does the PPB’s device registration process work well for AI models that change after approval?
The Medical Device Software guideline requires manufacturers to define permitted model evolution and build in rollback capability, but whether PPB’s existing variation-notification process, designed for static physical devices, functions smoothly for a continuously updating model is not yet clearly resolved in published materials.
Does complying with the MDSW guideline also satisfy Kenya’s data protection law?
No. An AI SaMD processing patient data separately triggers Data Protection Act 2019 obligations, including data handler registration and, for sensitive categories like genetic data, a Data Protection Impact Assessment. These are independent of PPB device compliance.
Who is liable if an adaptive AI medical device causes harm through an autonomous error?
Kenya has no specific statute or reported case law addressing this scenario directly. Ordinary negligence and product liability principles would likely apply in some form, but how they apply to a model that changed after PPB approval is untested.



